Netskope Threat Labs

Tonedeaf

ATP Sandbox Adv. HeuristicsAV

ToneDeaf is a backdoor trojan associated with state sponsored actors that targets organizations for data collection through staged command and control. It reaches victims via malicious documents, and its implant collects files and system information while blending its channels into ordinary web traffic. Detections under this name indicate targeted espionage activity rather than commodity criminal malware.

First seen
February 2023
Last seen
October 2026
ToneDeaf
Alert Name
DeepScan:Generic.Tonedeaf.3.2D543AC8
Document-Excel.Trojan.ToneDeaf
Dump:Generic.ToneDeaf.1.FFFFFFFE
Dump:Generic.Tonedeaf.3.2D543AC8
Generic.ToneDeaf.1.4930F6E5
Generic.ToneDeaf.2.1A18E2C4
Generic.ToneDeaf.2.23795C40
Generic.ToneDeaf.2.251318FB
Generic.ToneDeaf.2.3BA44B65
Generic.ToneDeaf.2.522272AD